Requesting PCAP from PX using NX L7 metadata

Prev Next

A Packet Capture appliance stores only PCAP while paired with an Network Security appliance. L7 metadata from the NX appliance can be used by the NDR to identify PCAP from the Packet Capture.

Perform the following steps on NDR:

  1. Login to NDR CLI.

  2. Create client profile.

    For more information on how to create a client profile see, Creating a client profile using the CLI.

  3. Create client group.

    For more information on how to create a client profile see, Creating a client group using the CLI.

    1. In the add new group window, type 7 to add a PX host.

      Note

      PX_host.png
    2. Type X to save and return to the client group configuration page.

  4. The client group generates a token, use this token to configure L7 metadata export on NX.

To retrieve PCAP from an Network Security-paired Packet Capture appliance:

  1. Log in to the NDR Web UI.

  2. Select Search > Summary tab.

  3. In the Query bar:

    1. Enter the search query "sensor_type: nx".

    2. Select a window of time to search for event metadata ingested from the Packet Capture.

    3. Click the search button.

  4. The PX event table displays Packet Capture events that correspond to events on the paired Network Security appliance. Information in the event table helps determine which Network Security event the PCAP pertains to.

  5. Perform session reconstruction. Select the event from the search results and then click the Reconstruct icon.

    Reconstruct.png